with verified answers
Access control systems Ans✓✓✓The strongest and most recognizable
intrusion protection systems used by organizations large and small.
administrative or internal investigations Ans✓✓✓-are often the starting
point of a significant set of activities, such as civil or criminal
investigations
-conducted when the entirety of the process will be contained within the
organization; it exists solely as an internal function
-Administrative investigations are usually carried out when an incident
is the result of an authorized user acting maliciously or inadvertently,
causing damage or bringing risk to the organization.
After examining the network activity log files, nothing springs out as an
indicator of an external attack. However, looking at the UEBA logs you
notice that one of your employees, Sasha Coen, is being flagged. She is
accessing the customer accounts files at odd times, usually outside of her
normal working hours. What would need to be examined?
Ans✓✓✓Sasha's work computer
All-Source Intelligence Ans✓✓✓describes the inputs and the processes
used to derive actionable assertions, recommendations and conclusions
to inform decision making.
Author Identification Ans✓✓✓involves attempts to determine who
created or authored the software/program in question (was it an
,individual or group effort). The code is examined for clues to
programming style, program language, development toolkits used,
embedded comments and addresses and so on.
chain of custody Ans✓✓✓is the sequence of records kept about each
piece of evidence, showing every step in its history.
change to evidence handling and Ans✓✓✓evidence gathering may exist
in many different formats such as a disk image, log files, memory
content or physical evidence.
a cryptographic has should be calculated and recorded to detect data
alterations that occur after imaging.
checklists Ans✓✓✓-can provide a powerful but simple set of
reminders, either of criteria to assess an event with current conditions to
check.
civil investigation Ans✓✓✓-civil law applies when a victimized entity
sues the offensive party.
-An investigation with intended purpose of a lawsuit should involve the
same degree of documentation and adherence to detail as a criminal
investigation.
Clipping levels Ans✓✓✓are a predefined criterion, or threshold, that
sets off an event entry. For example, a security operations center does
not want to be notified of every failed login attempt, because everyone
, mistypes their password occasionally. Thus, set the clipping level to
only create a log entry after two failed password attempts.
containment strategy should be driven by several criteria including the
following: Ans✓✓✓-need to preserve forensic evidence for possible
legal actions
-Availability of services the affected component provides
-Potential damage leaving the affected component in place may cause
-Time required for the containment strategy to be effective
-resources required to contain the affected component
Content Analysis Ans✓✓✓involves the systematic analysis of the
purpose of the code. In the case of Trojan horse programs, for example,
the focus would be on determining what the actual attack was meant to
do, what and where files were installed or altered on the infected
systems, what communications channels were opened (ingress and
egress), the identification of any upstream destination addresses, what
information was being sent or stored locally for batch uploads, etc.
Context Analysis Ans✓✓✓refers to developing a meta view of the
impact of the suspicious software relative to the case or the environment
in which it was found. Understanding context can assist with the
analysis and can be used to develop a realistic rating of the risks to the
organization or victim.
correlation does this by grouping data from these streams in several
ways: Ans✓✓✓-time correlations